“Sovereign cloud” has become a common sales label. It appears on very different offers: a data centre in France run by a subsidiary of a US group, a French host that hands part of its service to non-European subcontractors, a service qualified by ANSSI. All talk about sovereignty; they do not protect data in the same way. The difference lies almost entirely in a question the sales pitch avoids: which law is the host subject to?
Answering it requires understanding what the US CLOUD Act allows, why data location is not enough to protect against it, and how to check what sovereign hosting really guarantees.
The CLOUD Act in a few lines
The CLOUD Act is a US law passed in March 2018. It clarifies that a service provider subject to US law must disclose to US authorities, when required in legal proceedings, data in its possession, custody or control, whether that data is stored in the United States or elsewhere. Storage location is therefore not the criterion: the link between the provider and US law is.
The law also provides for bilateral agreements with other states, organising reciprocal access to electronic evidence. The US Department of Justice lists such agreements with the United Kingdom and Australia; negotiations with the European Union resumed in 2023. Nor is it the only text at issue: the Court of Justice of the EU’s Schrems II judgment relied on the access possibilities available to US intelligence services under other provisions to strike down, in 2020, the transfer framework then in force.
What this means for a business is simple: entrusting data to a provider subject to US law, even one hosting in France, amounts to accepting that a foreign authority may demand access to it under rules that are not its own. That risk may be acceptable for much data. It is not for all of it.
Data location and applicable law: the difference
Confusing the two notions explains most misunderstandings about the sovereign cloud.
| Criterion | Data location | Law applicable to the operator |
|---|---|---|
| Question asked | Where are the servers physically? | Which laws is the operating company subject to? |
| What it guarantees | That the GDPR applies to the processing | That no foreign law can require the data to be handed over |
| How to check it | Location clause in the contract | Registered office, ownership, control, subcontractors |
An offer can meet the first condition without the second. That is the case with the European regions offered by the major US providers: the data stays in Europe, and the operator remains subject to US law. These offers have other qualities — breadth of features, maturity, often solid contractual commitments — but they do not answer the jurisdiction question.
Between the two ends, the market has several families of offers, which need to be recognised: European hosts without qualification, whose jurisdiction is European but whose guarantees are not verified by a third party; offers that run a major US provider’s technology under licence, operated by a separate European entity, some of which are seeking qualification; and services that are actually qualified. Each meets a different level of requirement, and the same word is used for all of them.
What a sovereign cloud guarantees
In France, the benchmark is the SecNumCloud qualification issued by ANSSI. Its version 3.2 includes explicit requirements for protection against extraterritorial laws. According to ANSSI’s FAQ, they concern in particular:
- the provider’s registered office, which must be established in an EU member state;
- its ownership, in which entities located outside the Union must remain in the minority;
- the use of non-European third parties, which is limited, without their being able to access the data;
- location within the Union of customer data, account directories and technical data such as logs.
Two clarifications matter. Qualification applies to a specific offer, not to a provider: a host qualified for one service is not qualified for its whole catalogue. And it now carries regulatory weight for the State: the law of 21 May 2024 requires administrations to protect their most sensitive data hosted by a private provider against unauthorised access by third-country authorities, and an order of 12 August 2026 approved the SecNumCloud 3.2 framework for that purpose. Private businesses are not covered; many nonetheless use it as a benchmark.
What a sovereign cloud does not guarantee should also be said. It does not protect against poor configuration, a weak password or a careless employee. It does not replace GDPR obligations, nor the processing contract. It does not always offer the same services as the largest providers, and it may cost more. Sovereignty answers one specific risk — access by a foreign authority — and that one only.
How to check a sovereign host
Most of a host’s commitments can be checked on documents. Five points are enough to tell a sovereign offer from one that borrows its vocabulary.
- Qualification. If the offer claims SecNumCloud qualification, the exact service must appear in ANSSI’s catalogue. “Qualification in progress” is not a qualification.
- Control. Who owns the capital, and who really controls the company? A French subsidiary of a non-European group remains exposed to its parent company’s law.
- The subcontracting chain. Which providers are involved — support, maintenance, software —, where are they established, and can they access the data?
- Contract clauses. Governing law and competent jurisdiction, location of data and logs, a commitment to inform the client of any access request from an authority, reversibility.
- Encryption keys. Who holds them? Encrypted data whose keys the host does not hold is far less exposed, whatever law it is subject to.
Each of these points calls for a document, not an assertion: the extract from ANSSI’s catalogue, the list of sub-processors annexed to the contract, the governing-law and jurisdiction clauses, the description of key management. A serious host provides them without difficulty. One that answers with a brochure or an argument of principle signals, without saying so, what it cannot document.
These checks apply to artificial intelligence too. A generative AI service hosted on a sovereign cloud inherits its guarantees; run by a provider subject to US law, it inherits its exposure. The options are compared in the same way — as set out in local AI compared with the sovereign cloud and US offers — and fit into the wider question of what sovereign AI changes for a business.
For a business wanting to go further than hosting — so that no third party, even a European one, sits on the route of its data —, there remains execution on dedicated hardware. That is the approach of Maeliom’s sovereign AI offer, in early access: inference runs on hardware installed in France, with no subcontracting of the processing.
Common questions
Is data hosted in France protected from the CLOUD Act?
Not if the host is subject to US law. The CLOUD Act applies to data controlled by a provider falling under that law, wherever it is stored. Protection depends on the operator’s jurisdiction, not on location.
What is SecNumCloud qualification?
It is a qualification issued by ANSSI to a specific cloud offer, attesting a high security level and, since version 3.2, protection against extraterritorial laws. It can be checked in the catalogue published by ANSSI.
Is encryption enough to protect against the CLOUD Act?
It greatly reduces exposure, on one condition: that the keys are held by the business or an independent third party, not by the host itself. A provider that holds the keys to encrypted data can be compelled to decrypt it. Encryption also protects less well data being processed, which the service must read to function.
Is sovereign hosting mandatory for a private business?
As a rule, no. Recent obligations apply to State administrations. But some sectors, some public-sector clients and some contracts require it in practice, and the sensitivity of the data can justify it.
Sources: US Department of Justice, CLOUD Act resources; 18 U.S.C. § 2713; CJEU, C-311/18; ANSSI, SecNumCloud qualification FAQ and catalogue of qualified solutions; Law No. 2024-449; Order of 12 August 2026.